CVE-2013-2240: Menalto Gallery

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

Affected products

  • Menalto Gallery: version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.0.5 only; …

Published 2013-10-10. Last modified 2026-06-16.